Umngcipheko woTshintsho: Ufunyaniswa njani uPhakamo lweLungelo kuMlawuli weDomain

Ifunyenwe kulo nyaka ukuba sesichengeni kuTshintsho ivumela nawuphi na umsebenzisi we-domain ukuba afumane amalungelo omlawuli we-domain kunye nokuthomalalisa i-Active Directory (AD) kunye nezinye iinginginya eziqhagamshelweyo. Namhlanje siza kukuxelela indlela olu hlaselo lusebenza ngayo kunye nendlela yokulufumana.

Umngcipheko woTshintsho: Ufunyaniswa njani uPhakamo lweLungelo kuMlawuli weDomain

Nantsi indlela olu hlaselo lusebenza ngayo:

  1. Umhlaseli uthatha iakhawunti yakhe nawuphi na umsebenzisi wedomeyini ngebhokisi yeposi esebenzayo ukuze abhalisele isiciko sesaziso sokutyhala esivela kuTshintsho.
  2. Umhlaseli usebenzisa i-NTLM relay ukukhohlisa umncedisi woTshintshiselwano: ngenxa yoko, iseva yoTshintshiselwano idibanisa kwikhompyutheni yomsebenzisi ophazamisekileyo usebenzisa i-NTLM phezu kwendlela ye-HTTP, apho umhlaseli ayisebenzisayo ukuqinisekisa kumlawuli wesizinda nge-LDAP nge-akhawunti yoTshintsho lweziqinisekiso.
  3. Umhlaseli uphela esebenzisa ezi ziqinisekiso zeakhawunti yoTshintsho ukunyusa amalungelo abo. Eli nyathelo lokugqibela linokwenziwa ngumlawuli onobutshaba osele enofikelelo olusemthethweni ukwenza utshintsho oluyimfuneko lwemvume. Ngokudala umgaqo wokubona lo msebenzi, uya kukhuselwa kule nto kunye nokuhlaselwa okufanayo.

Emva koko, umhlaseli anokuthi, umzekelo, aqhube i-DCSync ukufumana amagama ayimfihlo akhawulezayo kubo bonke abasebenzisi kwisizinda. Oku kuya kumvumela ukuba enze iintlobo ezahlukeneyo zokuhlaselwa - ukusuka kuhlaselo lwetikiti legolide ukuya kwi-hash transmission.

Iqela lophando lweVaronis liye lafunda le vector yokuhlaselwa ngokubanzi kwaye yalungiselela isikhokelo kubathengi bethu ukuba basibhaqe kwaye ngexesha elifanayo bahlole ukuba sele bephazamisekile.

UkuFunyaniswa kokuNyuswa kweLungelo leDomain

В DataAlert Yenza umgaqo wesiko ukulandelela utshintsho kwiimvume ezithile kwizinto. Iya kuqhutywa xa isongeza amalungelo kunye neemvume kwinto enomdla kwisizinda:

  1. Chaza igama lomgaqo
  2. Seta udidi "Unyuso lwelungelo"
  3. Cwangcisa uhlobo lobutyebi ku "Zonke iindidi zoovimba"
  4. Umncedisi weFayile = IiNkonzo zeeNkonzo
  5. Chaza i-domain onomdla kuyo, umzekelo, ngegama
  6. Yongeza icebo lokucoca ukongeza iimvume kwi AD into
  7. Kwaye ungalibali ukushiya ukhetho "Khangela kwizinto zomntwana" ungakhethwanga.

Umngcipheko woTshintsho: Ufunyaniswa njani uPhakamo lweLungelo kuMlawuli weDomain

Kwaye ngoku ingxelo: ukufumanisa utshintsho kumalungelo kwinto yesizinda

Utshintsho kwiimvume ze-AD lunqabile, ngoko ke nantoni na ebangele esi silumkiso kufuneka kwaye iphandwe. Kuya kuba ngumbono olungileyo ukuvavanya inkangeleko kunye nomxholo wengxelo ngaphambi kokuqalisa umthetho ngokwawo edabini.

Le ngxelo iya kubonisa ukuba sele uchaphazelekile kolu hlaselo:

Umngcipheko woTshintsho: Ufunyaniswa njani uPhakamo lweLungelo kuMlawuli weDomain

Nje ukuba umthetho usebenze, ungaphanda zonke ezinye iziganeko zokunyuka kwamalungelo usebenzisa ujongano lwewebhu lweDatAlert:

Umngcipheko woTshintsho: Ufunyaniswa njani uPhakamo lweLungelo kuMlawuli weDomain

Nje ukuba uqwalasele lo mgaqo, ungabeka iliso kwaye ukhusele kwezi kunye neendidi ezifanayo zobuthathaka bokhuseleko, uphande ngeziganeko ngeenkonzo zolawulo lwe-AD, kwaye ubone ukuba uyachaphazeleka kobu buthathaka bubalulekileyo.

umthombo: www.habr.com

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster